CVE-2026-55425
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated user to request composite display fields without verifying that every selected field is readable. A user can retrieve protected values, including the password hash on a readable user record; ordinary users are limited to their own permitted records, while administrators can retrieve hashes for all users. This issue is fixed in versions 7.1.4 and 7.2.0-alpha.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- EPSS probability
- 0.30%
- CWE
- CWE-213
- Published
- 2026-08-28
- Last modified
- 2026-08-31
Affected products
- Graylog2 graylog2-server
- Graylog2 graylog2-server
Weakness type
Related vulnerabilities
- CVE-2026-56538 — HCL Connections is vulnerable to information disclosure
- CVE-2026-6280 — Improper Access Control in Nomysoft Informatics' Nomysem
- CVE-2025-52603 — HCL Connections is vulnerable to information disclosure
- CVE-2025-54831 — Apache Airflow: Connection sensitive details exposed to users with READ permissions
- CVE-2024-49827 — IBM Concert Software information disclosure
- CVE-2025-4976 — Exposure of Sensitive Information Due to Incompatible Policies in GitLab
- CVE-2025-32791 — Permission policy information leakage in Backstage permission system
- CVE-2025-24316 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policies